Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill instructs the agent to read and write project files and invoke shell commands (Python, ffmpeg, OS-native open commands), but it declares no corresponding permissions. This creates a trust and containment gap: a caller or runtime may assume the skill is low-privilege while it actually performs filesystem and command execution operations, increasing the risk of unintended file access, overwrites, or command misuse if the skill is invoked on untrusted project content or paths.
